Class AciHandler
- java.lang.Object
-
- org.opends.server.api.AccessControlHandler<DseeCompatAccessControlHandlerCfg>
-
- org.opends.server.authorization.dseecompat.AciHandler
-
public final class AciHandler extends AccessControlHandler<DseeCompatAccessControlHandlerCfg>
The AciHandler class performs the main processing for the dseecompat package.
-
-
Constructor Summary
Constructors Constructor Description AciHandler()Creates a new DSEE-compatible access control handler.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description voidfilterEntry(Operation operation, SearchResultEntry unfilteredEntry, SearchResultEntry filteredEntry)Filter the contents of the provided entry such that it no longer contains any attributes or values that the client is not permitted to access.voidfinalizeAccessControlHandler()Performs any necessary finalization for the access control handler implementation.voidinitializeAccessControlHandler(DseeCompatAccessControlHandlerCfg configuration)Initializes the access control handler implementation based on the information in the provided configuration entry.booleanisAllowed(DN entryDN, Operation op, Control control)Indicates whether the provided control is allowed based on the access control configuration and the specified operation.booleanisAllowed(BindOperation bindOperation)Indicates whether the provided bind operation is allowed based on the access control configuration.booleanisAllowed(ExtendedOperation operation)Indicates whether the provided extended operation is allowed based on the access control configuration.booleanisAllowed(ModifyDNOperation operation)Checks access on a modifyDN operation.booleanisAllowed(SearchOperation searchOperation)Indicates whether the provided search operation is allowed based on the access control configuration.booleanisAllowed(Operation operation, Entry entry, SearchFilter filter)Indicates whether the provided operation search filter is allowed based on the access control configuration.booleanisAllowed(LocalBackendAddOperation operation)Indicates whether the provided add operation is allowed based on the access control configuration.booleanisAllowed(LocalBackendCompareOperation operation)Check access on compare operations.booleanisAllowed(LocalBackendDeleteOperation operation)Check access on delete operations.booleanisAllowed(LocalBackendModifyOperation operation)Indicates whether the provided modify operation is allowed based on the access control configuration.booleanmayProxy(Entry proxyUser, Entry proxiedUser, Operation op)Indicates if the specified proxy user entry can proxy, or act on the behalf of the specified proxied user entry.booleanmaySend(DN dn, Operation operation, SearchResultReference reference)Indicates whether the provided search result reference may be sent to the client based on the access control configuration.booleanmaySend(Operation operation, SearchResultEntry entry)Indicates whether the provided search result entry may be sent to the client.-
Methods inherited from class org.opends.server.api.AccessControlHandler
canDiscloseInformation, isConfigurationAcceptable
-
-
-
-
Method Detail
-
filterEntry
public void filterEntry(Operation operation, SearchResultEntry unfilteredEntry, SearchResultEntry filteredEntry)
Description copied from class:AccessControlHandlerFilter the contents of the provided entry such that it no longer contains any attributes or values that the client is not permitted to access.- Specified by:
filterEntryin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
operation- The operation currently being processed (this will usually be a search, but may be other types of operation when pre/post read controls are used).unfilteredEntry- The result entry before any attribute filtering.filteredEntry- The partially filtered result entry being returned to the client.
-
finalizeAccessControlHandler
public void finalizeAccessControlHandler()
Description copied from class:AccessControlHandlerPerforms any necessary finalization for the access control handler implementation. This will be called just after the handler has been deregistered with the server but before it has been unloaded.- Specified by:
finalizeAccessControlHandlerin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>
-
initializeAccessControlHandler
public void initializeAccessControlHandler(DseeCompatAccessControlHandlerCfg configuration) throws ConfigException, InitializationException
Description copied from class:AccessControlHandlerInitializes the access control handler implementation based on the information in the provided configuration entry.- Specified by:
initializeAccessControlHandlerin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
configuration- The configuration object that contains the information to use to initialize this access control handler.- Throws:
ConfigException- If an unrecoverable problem arises in the process of performing the initialization.InitializationException- If a problem occurs during initialization that is not related to the server configuration.
-
isAllowed
public boolean isAllowed(DN entryDN, Operation op, Control control) throws DirectoryException
Description copied from class:AccessControlHandlerIndicates whether the provided control is allowed based on the access control configuration and the specified operation. This method should not alter the provided operation in any way.- Specified by:
isAllowedin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
entryDN- A DN that can be used in the access determination.op- The operation to use in the determination.control- The control for which to make the determination.- Returns:
trueif the control should be allowed by the access control configuration, orfalseif not.- Throws:
DirectoryException- If an error occurred while performing the access control check. For example, if an attribute could not be decoded. Care must be taken not to expose any potentially sensitive information in the exception.
-
isAllowed
public boolean isAllowed(ExtendedOperation operation)
Description copied from class:AccessControlHandlerIndicates whether the provided extended operation is allowed based on the access control configuration. This method should not alter the provided extended operation in any way.- Specified by:
isAllowedin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
operation- The operation for which to make the determination.- Returns:
trueif the operation should be allowed by the access control configuration, orfalseif not.
-
isAllowed
public boolean isAllowed(LocalBackendAddOperation operation) throws DirectoryException
Description copied from class:AccessControlHandlerIndicates whether the provided add operation is allowed based on the access control configuration. This method should not alter the provided add operation in any way.- Specified by:
isAllowedin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
operation- The operation for which to make the determination.- Returns:
trueif the operation should be allowed by the access control configuration, orfalseif not.- Throws:
DirectoryException- If an error occurred while performing the access control check. For example, if an attribute could not be decoded. Care must be taken not to expose any potentially sensitive information in the exception.
-
isAllowed
public boolean isAllowed(BindOperation bindOperation)
Description copied from class:AccessControlHandlerIndicates whether the provided bind operation is allowed based on the access control configuration. This method should not alter the provided bind operation in any way.- Specified by:
isAllowedin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
bindOperation- The operation for which to make the determination.- Returns:
trueif the operation should be allowed by the access control configuration, orfalseif not.
-
isAllowed
public boolean isAllowed(LocalBackendCompareOperation operation)
Check access on compare operations. Note that the attribute type is unavailable at this time, so this method partially parses the raw attribute string to get the base attribute type. Options are ignored.- Specified by:
isAllowedin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
operation- The compare operation to check access on.- Returns:
- True if access is allowed.
-
isAllowed
public boolean isAllowed(LocalBackendDeleteOperation operation)
Check access on delete operations.- Specified by:
isAllowedin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
operation- The delete operation to check access on.- Returns:
- True if access is allowed.
-
isAllowed
public boolean isAllowed(ModifyDNOperation operation)
Checks access on a modifyDN operation.- Specified by:
isAllowedin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
operation- The modifyDN operation to check access on.- Returns:
- True if access is allowed.
-
isAllowed
public boolean isAllowed(LocalBackendModifyOperation operation) throws DirectoryException
Description copied from class:AccessControlHandlerIndicates whether the provided modify operation is allowed based on the access control configuration. This method should not alter the provided modify operation in any way.- Specified by:
isAllowedin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
operation- The operation for which to make the determination.- Returns:
trueif the operation should be allowed by the access control configuration, orfalseif not.- Throws:
DirectoryException- If an error occurred while performing the access control check. For example, if an attribute could not be decoded. Care must be taken not to expose any potentially sensitive information in the exception.
-
isAllowed
public boolean isAllowed(SearchOperation searchOperation)
Description copied from class:AccessControlHandlerIndicates whether the provided search operation is allowed based on the access control configuration. This method may only alter the provided search operation in order to add an opaque block of data to it that will be made available for use in determining whether matching search result entries or search result references may be allowed.- Specified by:
isAllowedin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
searchOperation- The operation for which to make the determination.- Returns:
trueif the operation should be allowed by the access control configuration, orfalseif not.
-
isAllowed
public boolean isAllowed(Operation operation, Entry entry, SearchFilter filter) throws DirectoryException
Description copied from class:AccessControlHandlerIndicates whether the provided operation search filter is allowed based on the access control configuration. This method should not alter the provided operation in any way.- Specified by:
isAllowedin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
operation- The operation for which to make the determination.entry- The entry for which to make the determination.filter- The filter to check access on.- Returns:
trueif the operation should be allowed by the access control configuration, orfalseif not.- Throws:
DirectoryException- If an error occurred while performing the access control check. For example, if an attribute could not be decoded. Care must be taken not to expose any potentially sensitive information in the exception.
-
mayProxy
public boolean mayProxy(Entry proxyUser, Entry proxiedUser, Operation op)
Description copied from class:AccessControlHandlerIndicates if the specified proxy user entry can proxy, or act on the behalf of the specified proxied user entry. The operation parameter is used in the evaluation.- Specified by:
mayProxyin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
proxyUser- The entry to use as the proxy user.proxiedUser- The entry to be proxied by the proxy user.op- The operation to use in the evaluation.- Returns:
trueif the access control configuration allows the proxy user to proxy the proxied user, orfalseif not.
-
maySend
public boolean maySend(DN dn, Operation operation, SearchResultReference reference)
Description copied from class:AccessControlHandlerIndicates whether the provided search result reference may be sent to the client based on the access control configuration.- Specified by:
maySendin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
dn- A DN that can be used in the access determination.operation- The operation with which the provided reference is associated.reference- The search result reference for which to make the determination.- Returns:
trueif the access control configuration allows the reference to be returned to the client, orfalseif not.
-
maySend
public boolean maySend(Operation operation, SearchResultEntry entry)
Description copied from class:AccessControlHandlerIndicates whether the provided search result entry may be sent to the client. Implementations must not under any circumstances modify the search entry in any way.- Specified by:
maySendin classAccessControlHandler<DseeCompatAccessControlHandlerCfg>- Parameters:
operation- The operation currently being processed (this will usually be a search, but may be other types of operation when pre/post read controls are used).entry- The result entry before any attribute filtering.- Returns:
trueif the access control configuration allows the entry to be returned to the client, orfalseif not.
-
-